Skip to content

[DEVPL-4096] Patch high-severity vulnerable dependency#337

Merged
tim-webflow merged 1 commit intomasterfrom
socket/dependency-fix-20260407
Apr 17, 2026
Merged

[DEVPL-4096] Patch high-severity vulnerable dependency#337
tim-webflow merged 1 commit intomasterfrom
socket/dependency-fix-20260407

Conversation

@ping-huang1
Copy link
Copy Markdown
Contributor

fix: upgrade dependency to fix high vulnerability (GHSA-xjpj-3mr7-gcpf)

Summary

https://webflow.atlassian.net/browse/DEVPL-4096

Resolves a High severity JavaScript injection vulnerability in handlebars (GHSA-xjpj-3mr7-gcpf) using socket fix.

The Handlebars CLI precompiler unsafely concatenates user-controlled inputs (template names, --namespace, -c, -h flags) directly into generated JavaScript, allowing arbitrary code injection. CVSS Score: 8.2 (High)

Fix was computed via:

npx socket fix --id GHSA-xjpj-3mr7-gcpf

@tim-webflow tim-webflow merged commit 13d36fc into master Apr 17, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants